Re: SMAC by-pass hack?
Don't tell me ufw and iptables feel like working now ://////
|
Re: SMAC by-pass hack?
Connected.
|
Re: SMAC by-pass hack?
We had a talk and he tested some stuff on me.
Looks like it ain't working. The only servers who have been able to successfully ban me was Team Cream servers. That was long ago, though. Edit: I tested on them again. They were able to ban me. |
Re: SMAC by-pass hack?
Ok so this also works on skial
When I trigger an SMAC ban on myself, the sourcebans page shows STEAM_ID_STOP_IGNORING_RETVALS STEAM_0:0:0 76561197960265728 <---- profile link, but it leads to nothing https://puu.sh/xLy18/a5ddcc561f.png Oh, and I can still join their other servers. I believe after a while I can join the one I was banned from. Admins also try to manually ban me from the server via the Sourcebans page, but it doesn't do crap because I have no steamid in the server! |
Re: SMAC by-pass hack?
EDIT 2018-04-12:
This hack of a method has been fixed and optimized, integrated into an auto-updating central plugin: Source Download Link
Spoiler
|
Re: SMAC by-pass hack?
The weird thing is, and I guess this is expected behavior, but Connect can get the SteamIDs just fine. I guess now we just need to figure out a way to force it on a client or something, iunno. An extension or native that would force IDs would fix a bunch of other problems too.
|
Re: SMAC by-pass hack?
If
Code:
GetClientAuthId(client, AuthId_Steam2, auth, sizeof(auth) Code:
IsAuthorized(client); If GetClientAuthId returns FALSE, and you're still using the contents of "auth", that is when when you're getting "STEAM_ID_STOP_IGNORING_RETVALS", it should not be returning TRUE at the same time as providing "STEAM_ID_STOP_IGNORING_RETVALS". Even the very old GetClientAuthString, says the same as the newer GetClientAuthId: Code:
Return: Code:
Return Value
Many years ago, I started out with some plugins here from AM, then I changed to my own plugins, and/or re-built them to suit my needs better. Many of them was using like the above example I made in POST #5. I ended up on having a lot of issues, sometimes with empty or invalid Steam ID's, and when I finally saw the documentaiton, I found that the plugins wasn't doing things according to the API (checking TRUE vs FALSE return value) I then changed things from: Code:
GetClientAuthString(client, SteamID, sizeof(SteamID)); Code:
new bool:bSteam32 = GetClientAuthString(client, SteamID, sizeof(SteamID)); I don't intend to be rude, but for plugin creators, the thing is very simple - make sure to follow the documentation 100%. That worked for me when creating my plugins, as well as when fixing broken plugins created by others. For the above "temp fix", I would rather suggest kicking people, like SMAC does, if the player hasn't validated within like 15, 30, 45 or 60 seconds - depending on what you prefer. 15 seconds should usually be enough, unless the Steam network is down. OnClientPostAdminCheck will never be called, if Steam network is down (or STEAM_ID_PENDING / STEAM_ID_STOP_IGNORING_RETVALS), and therefore I usually suggest using that one for "on-connect" things when you need to know who they really are. |
Re: SMAC by-pass hack?
Quote:
|
Re: SMAC by-pass hack?
Makes sense. Just did a bit of checking with below:
Spoiler
and it seemed to reach 3 consecutively. Do you know if downned Steam servers might trip up GetClientAuthId? If it does, then would kicking also false-positive? |
Re: SMAC by-pass hack?
Go for it. It's been live and worked for me all last night. I just am really unsure about false-positives if Steam servers are down.
|
All times are GMT -4. The time now is 20:27. |
Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.